3 ms·
>Because the chat app doesn't encrypt conversations by default—or at all for group chats—security professionals often warn against it. Everytime this story com
by s_dev 6y ago
>Because the chat app doesn't encrypt conversations by default—or at all for group chats—security professionals often warn against it.
Everytime this story comes up it just complains about the default setting.
Terribly reasearched articled. It offeres no insight to HNers compared to previous discussion. A bad workman blames his tools. Defaults are powerful -- I will concede. Not understanding defaults counts as not understanding your tool.
I don't even believe WhatsApp is E2E but I've no evidence to proove that -- I'm just that skeptical of FB. I believe FB are reading WA messages but again -- nothing to base that on other than FB being heavily incentived to do so.
- goatinaboat 6y agoTerribly reasearched article It’s not an article, it’s a hit piece. Established publication protecting established vendor. Classic Wired.
- s_dev 6y agoYou reckon this is PR paid for by FB and expressed in the media via Wired?
- stelonix 6y agoAlthough I'm not the original commenter, direct cash payment isn't the only incentive for established media to protect established product. Let's not forget they're apps from different, rival countries.
- JetSpiegel 6y agoWhy would they interview only other Facebook-adjacent people? It's even disclosed on TFA.
- tw04 6y agoThe journalist is just wrong. Security professionals don't warn against it because it doesn't encrypt by default, they warn against it because Telegram wrote their own encryption protocol and they haven't allowed an outside audit. Basically "trust us we know what we're doing. If something has changed feel free to correct me, but as far as I know MTProto is still all in-house closed source code and hasn't ever been audited. https://eprint.iacr.org/2015/1177.pdf https://eprint.iacr.org/2015/1177.pdf
- akvadrako 6y agoThere was some analysis done recently, though not being a crypto expert I don't know how relevant it is: https://news.ycombinator.com/item?id=25722076#25724978 https://news.ycombinator.com/item?id=25722076#25724978 One note: Telegram doesn't need to "allow" experts to audit their code - E2E is all in the clients which have source available. I don't think it's had enough scrutiny to be trustworthy though.
- lozf 6y ago> E2E is all in the clients But only mobile clients, no E2E on the desktop or for groups sadly.
- nguyenkien 6y agoMac client has it. The one written with swift. In Windows you have Unigram (unofficial, but opensource)
- lozf 6y agoInteresting thanks. Maybe it'll get to Linux one day then. Not that I'm too fussed, I use telegram for larger groups mostly, and secure chats on Signal.
- s_dev 6y agoI'm aware "roll your own crypto" is bad practice but MTProto is open to being inspected: https://core.telegram.org/mtproto https://core.telegram.org/mtproto https://github.com/tdlib/td/tree/80c35676a2eb1e9b71db355ee217bba79fbdce31/td/mtproto https://github.com/tdlib/td/tree/80c35676a2eb1e9b71db355ee21...